
Configuring LDAP Services for Novell eDirectory
375
n
ov
do
cx (e
n)
11
Ju
ly 20
08
Referral Flitering
If you have multiple replica servers running in a tree and have configured LDAP server(s) to return
referrals using the Prefer Referrals/Always Refer option, then the LDAP server will return referrals
if the object identified by DN in the requested operation is not present locally. In such a case, LDAP
client sends a request to the server, and the server returns a referral list of all the LDAP servers
holding that object. Using this referral list, LDAP clients will follow any of these referrals to
perform the operation. If the client chooses to follow the referral to a lresouce starved server or a
server that is located across a slow link, clients would see a slow response from the server. This in
turn affects the performance of the LDAP client.
Since LDAP application developers will not have complete knowledge about the servers and
network configurations, the solution for this problem is to provide a referral filtering mechanism at
the LDAP server to return the referrals of specific server(s). Administrators would have the requisite
knowledge, e.g. the nature of LDAP servers in the network and network link speeds to make
appropriate configuration of referral filtering.
Set up the referral filter on the LDAP Group object using the attributes “referralIncludeFilter” and
“referralExcludeFilter”. Setting these filters in these attributes will be applicable to all the LDAP
servers belonging to this LDAP Group object. The LDAP server will return all the LDAP referrals
matching with the referralIncludeList filter and drop the ones that match the referralExcludeFilter
filter.
If only referralIncludeFilter is specified, the LDAP referrals which match the referralIncludeFilter
values will be returned to the LDAP clients and all other referrals will be excluded from the referral
list. Similarly, if only referralExcludeFilter is specified, the LDAP referrals which do not match the
referralExcludeFilter values will be returned to the LDAP clients. If both filters exist and the referral
does not match any of these filters, it will be excluded.
If all available referrals are disallowed by the filter, the server will behave as if no referrals are
available and return LDAP_OTHER (80), which some client tools report as "Unknown error". After
adding or modifying these filter attributes, if the LDAP server is not refreshed, changes will take
place after the subsequent automatic refresh.
Currently, adding or modifying these filter attributes can be done only with ther tab in ConsoleOne®
and iManager.
Format to Specify LDAP Referral Filtering
—The LDAP referral filter format is a simple IP
address format:
[ldap://] | [ldaps://]
IPAdress
[:port]
Here, specifying the clear text port or TLS port will be same as pre-pending ldap:// or ldaps://
strings. If neither ldap or ldaps is specified, the match filter is applicable for both clear text as well as
TLS referrals.
Examples:
Examples
Description
1.2.3.4
# matches both ldap and ldaps referrals on any port
1.2.
# matches all IP addresses of 1.2.X.Y
1.2.3.
# matches all IP addresses of 1.2.3.Y
Содержание EDIRECTORY 8.8 SP3
Страница 4: ...novdocx en 11 July 2008...
Страница 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 120: ...120 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 132: ...132 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 190: ...190 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 238: ...238 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 262: ...262 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 288: ...288 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 320: ...320 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 348: ...348 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 388: ...388 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 492: ...492 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 586: ...586 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 599: ...The eDirectory Management Toolbox 599 novdocx en 11 July 2008 Click Help for details...
Страница 600: ...600 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 614: ...614 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...